Defensible by Design: Rethinking Controversies Data
PRODUCT LAUNCH Scroll to the bottom to register for your free trial
In 2025, a ransomware campaign against Oracle's E-Business Suite left the data of over 100
EBS clients exposed. However, while the story made for bold headlines in the business press, for an investor holding Oracle, the news alone offered little direction.
What investors needed was clear indication as to how serious the event was, who was responsible, and what the company was doing about it.
Here lies the gap in many controversy feeds. Severity scores exist to triage: to identify which few controversies, across hundreds of headlines, warrant attention. But a score can guide that judgement only if the reasoning behind it can be unpacked.
A score can guide judgement only if the reasoning behind it can be unpacked.
Consider an analyst who opens the morning's alerts to find a holding flagged at eight out of ten. The number alone cannot tell them whether the event is a decade old, or active and escalating; whether the company was the direct cause or sits several tiers removed in a supplier's operations; or whether it has already been remediated. They are left with two options: escalate every high score, which returns them to the wall of flags the score was meant to reduce, or trust it blindly, carrying a risk into a portfolio that no one has actually weighed. In the absence of context, the severity score serves no functional purpose.
A controversy score built to be examined
The Impact Cubed Controversies dataset is built to be interrogated. Within it, the Oracle event resolves into a moderate severity score of 6.0 out of 10 but, much more importantly, the reasoning beneath the score is instantly accessible, with each event assessed against five stated criteria:
![]() | Scale | The magnitude of the harm |
![]() | Scope | How far it reaches |
![]() | Irremediability | Whether the damage can be undone |
![]() | Responsibility | Whether the company was a direct operator, a value-chain participant, or an investor |
![]() | Corrective Action | What the company has done in response |

Each value is shown rather than asserted, and every record links to its sources for full traceability.
Instead of a number they must trust blindly, investors receive a fully justified judgement that can be dissected and deployed to fit their mandate or investment objectives. And because Corrective Action feeds a time-decay mechanism, the score moves as a company responds: an issue being addressed decays, a severe and unaddressed one holds. Over time this becomes a live record of whether engagement is working, providing context that a static label could not.
What the Impact Cubed Controversies dataset provides
Developed in direct consultation with 14 institutional firms, among them pension funds, asset managers, and consultants, the Impact Cubed Controversies dataset was constructed around two core needs. The first is early warning: a daily refresh and targeted alerts mean a firm learns of an event quickly, and from a source it can act on, while there is still time to respond. The second is evidence: the five criteria and the linked sources tied to each event let a position be documented rather than inferred from a headline, equipping a stewardship team to engage, a compliance function to show how a holding was handled, and a portfolio manager to defend a decision made in response.
Over 10,000 issuers, extendable to further public or private names
12 distinct ESG themes
Conflict-zone flagging via the ACRE framework
Daily refresh, with configurable alerts on watchlists, thresholds, and themes
24 months of history as standard, extendable to 10 years
Delivered by data feed, platform, or API, with FactSet, Rimes, and Snowflake distribution on request
Conflict-Zone exposure: Grounded in recognised frameworks
Not every risk sits inside a company's own conduct. Some of it sits in where that conduct takes place.
The Impact Cubed Controversies dataset makes that exposure visible through the Armed Conflict Risk Exposure (ACRE) framework, an independently developed classification of countries exposed to conflict.
Any event linked to a country carrying a Red classification is flagged, this includes counties that meet one or more recognised conflict triggers: the UN Children and Armed Conflict list, binding measures of the International Court of Justice, and UN Security Council sanctions.
The design keeps the flag usable rather than editorial:
Binary and auditable: An event is either flagged or it is not, and any user can trace the reason.
Supplementary and separate: The flag sits alongside the controversy score without altering it.
Portfolio-ready: aggregates to the portfolio, so exposure reads as the share of portfolio weight sitting in flagged events rather than a scattered set of company footnotes.
The result is a single, defensible answer to a question investors are increasingly asked to evidence: how much of this portfolio is exposed to armed conflict?
Scroll down to register for your instant access trial
Integrated views: A further dimension
For firms that also license Impact Cubed's social dataset, each and every reported controversy can also be read against a company's structural profile to provide a more comprehensive picture.
Through the Controversies dataset, we can observe a cluster of workforce-safety controversies recorded at Amazon-operated sites within the last two years. Assessed on their own, these establish that serious, related events have occurred at the company's own facilities. What they cannot answer conclusively is whether such events are isolated, or symptomatic of how the company operates.

The Impact Cubed Social dataset supplies that context.
Amazon's recordable injury rate runs at 22 per million hours worked against a peer average of 11.4, almost double. The number of employee fatalities reported by Amazon in any given year is 3; the average for their industry is none. Drawing on these figures, we can interpret this data not as a description of any single incident but as a standing measure, sustained over time, of a company operating at an elevated level of workforce risk relative to its peers.
Read together, the two datasets turn discrete flags into a coherent picture: the controversies mark what happened, and the structural record indicates they sit on top of a persistently higher baseline. For a portfolio manager, a compliance function, or a stewardship team, that is the difference between logging an incident and understanding it.








Comments